Skip to content
Bakvora

Your data. Your keys. Your infrastructure.

Bakvora is designed so that nobody — including us — can read your backups.

Your datafiles · databasesPer-job data keyrandom AES-256Wrap #1 · your passwordPBKDF2-derived key → any PCWrap #2 · this machineWindows DPAPI → silent restoreencrypt

Envelope encryption, explained

Each job gets its own random AES-256 data key. That key is wrapped twice: once with a key derived from your job password using PBKDF2, and once with Windows DPAPI bound to the machine. On the original machine restores are seamless; on a new machine your password unlocks them. Lose both, and the data is unreadable — by design.

Credentials stay private

Database and network passwords are encrypted at rest and used only for the job they belong to. Network connections use per-job impersonation and never write anything to Windows Credential Manager. Application user passwords are salted and hashed, never stored in plain text.

No vendor cloud

Bakvora does not upload your files or databases anywhere except the destinations you configure. The only connections to our servers are license activation and update checks, which contain license and version information — never your backup content.

Tamper-resistant licensing & updates

Licenses are signed with RSA-2048 and bound to a hardware fingerprint. Updates are delivered by a dedicated updater that replaces the application only after the download completes.

Your part of the job

  • 1Keep job passwords in a password manager — we cannot recover them.
  • 2Follow the 3-2-1 rule: 3 copies, 2 media types, 1 off-site (FTP/SFTP helps).
  • 3Test a restore regularly — Bakvora makes it one click.

Your next backup is 5 minutes away

Try every feature free for 30 days. No credit card, no commitment.